SB2026090909 - Multiple vulnerabilities in Microsoft .NET Framework
Published: September 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 vulnerabilities.
1) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2026-57098)
CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper verification of cryptographic signatures in the Windows RDP Client when verifying cryptographic signatures. A remote attacker can trigger the improper signature verification to disclose sensitive information.
Successful exploitation may expose small portions of heap memory.
2) Code Injection (CVE-ID: CVE-2026-78463)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper control of generation of code in Remote Desktop Client when processing a malicious server response. A remote attacker can host a malicious server and convince a user to connect to it to execute arbitrary code.
User interaction is required.
3) Heap-based buffer overflow (CVE-ID: CVE-2026-80074)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Remote Desktop Client when processing a malicious server response. A remote attacker can host a malicious server and convince a user to connect to it to execute arbitrary code.
User interaction is required.
4) Heap-based buffer overflow (CVE-ID: CVE-2026-80077)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Remote Desktop Client when processing a server response. A remote attacker can host a malicious server and convince a user to connect to it to execute arbitrary code.
User interaction is required.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-57098
- https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/windowsdesktop-whatsnew
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-78463
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80074
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-80077